On September 30, 2025, the ransomware group LockBit5 added Incolease to its public leak site, claiming that it had exfiltrated internal files from International Company for Leasing S.A.E., an Egyptian leasing firm with nearly 5,000 LinkedIn followers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch incolease.com
Get alerted the next time incolease.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about incolease.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the company’s data appeared on the LockBit5 leak portal hosted on the dark web. Available details show the attackers claim to have stolen internal documents during a ransomware operation, though the exact volume of data and the specific types of records remain unclear from current postings. No confirmed victim count for individuals has been released, and the company has not yet issued a public statement detailing what was taken. The listing follows the group’s standard pattern of publishing samples and threatening full disclosure if demands are not met.
Why This Matters for You and Your Family
When a company that handles leasing contracts, payment records, or personal financial applications is breached, the information inside those files can include names, addresses, national ID numbers, bank details, and contact information belonging to ordinary customers. Internal files exfiltrated in such attacks often contain exactly the data that fuels identity theft, loan fraud, and unwanted marketing. If you or anyone in your family has ever financed a car, equipment, or property through a leasing company, your information could be among the records now sitting on a criminal leak site. The exposure creates a permanent risk because stolen data circulates for years among threat actors.
The Doxxing and Identity-Chain Implications
Leaked internal files frequently contain email addresses, phone numbers, and customer account details that link directly to social-media handles and gaming usernames. Once attackers possess one piece of the chain, they can map it to others, turning a single breach into repeated targeting. Credential leaks like this one regularly cascade into account takeovers on email, banking, and gaming platforms. Children’s gaming accounts are especially vulnerable because parents often reuse passwords or security questions tied to family addresses that appear in leasing records. The result is a growing web of doxxing that can expose your home address, family relationships, and daily routines.